Great Circle Associates Firewalls
(September 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Cisco Access Lists and NetFlow
From: Marc Mosko <marc @ tear . com>
Organization: Forte Systems
Date: Fri, 20 Sep 1996 13:04:47 -0700
To: gary flynn <gary @ habanero . jmu . edu>
Cc: firewalls @ GreatCircle . COM
References: <199609192150 . OAA28238 @ miles . greatcircle . com>

A flow is the complete source IP/port destination IP/port address. 
Netflow is no less secure than regular security lists.  It is vulerable
to IP spoofing just like regular lists.

The idea is that once a source IP/port is authorized for a destination
IP/port address, it does not need to be checked each time.  If nothing
changes -- the access list and the IP/port addresses -- then why check
every time?

I am not sure of the exact mechanics when an access list changes.  This
is what I would be worried about.  One would hope that all flows
pertaining to that list (and only those flows) would be re-authorized.


gary flynn wrote:
> "With Netflow Switching, only the first packet in a flow follows
> this process. If the first packet in a flow passes through these
> filters, an entry is added to the Netflow Switching cache. Subsequent
> packets in the same flow are then switched based on this cache
> entry, without needing to be matched against the complete set of
> access lists."
> 
> Has anyone analyzed the security implications of this when the
> router is being used in a firewall application? It sounds great
> for performance but off-hand, it also sounds like there is room
> for abuse.

-- 
   Marc Mosko                   Email: marc @
 tear .
 com
                                Web:   http://www.tear.com/

   "If anyone knocks out another's eye, he shall pay him
   sixty-six shillings, six pence, and a third of a penny."
   -- Leges Henrici Primi (13th century)

           PGP Key available via Public Servers and
               http://www.tear.com/pgp-key.html


References:
Indexed By Date Previous: Re: Internet connections without using Unix (fwd)
From: Rabid Wombat <wombat @ mcfeely . bsfs . org>
Next: RE: Re[2]: FW: NT vs. UNIX white paper
From: Jonathan Arcilla <jonats @ adn . edu . ph>
Indexed By Thread Previous: Cisco Access Lists and NetFlow
From: gary flynn <gary @ habanero . jmu . edu>
Next: Request for Information (Security for Educational Research Institute)
From: Don Weston <don @ admin . ogi . edu>

Google
 
Search Internet Search www.greatcircle.com